Jan 21 20:18:53 gateway1-old sshd[7546]: pam_unix(sshd:auth): authentication failure; logname= uid=0 ...
show moreJan 21 20:18:53 gateway1-old sshd[7546]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=38.250.149.61
Jan 21 20:18:54 gateway1-old sshd[7546]: Failed password for invalid user [email protected] from 38.250.149.61 port 31723 ssh2
Jan 21 20:18:58 gateway1-old sshd[7549]: Failed password for root from 38.250.149.61 port 31749 ssh2
show less
Detected Wordpress Scanning. - Request Method: GET - Target: {PC} wp-login.php - User Agent: N ...
show moreDetected Wordpress Scanning. - Request Method: GET - Target: {PC} wp-login.php - User Agent: N/A - Timestamp: 1/19/2026 4:15 pm (UTC-6)
show less
Web Spam
Hacking
Bad Web Bot
Web App Attack
Anonymous
Jan 17 17:30:21 www sshd\[24676\]: Invalid user [email protected] from 38.250.149 ...
show moreJan 17 17:30:21 www sshd\[24676\]: Invalid user [email protected] from 38.250.149.61
Jan 17 17:30:23 www sshd\[24680\]: Invalid user blenathan192 from 38.250.149.61
...
show less
Brute-Force
SSH
Anonymous
Jan 17 21:26:54 shubashi sshd[3717239]: pam_unix(sshd:auth): authentication failure; logname= uid=0 ...
show moreJan 17 21:26:54 shubashi sshd[3717239]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=38.250.149.61 user=[redacted]
Jan 17 21:26:56 shubashi sshd[3717239]: Failed password for [redacted] from 38.250.149.61 port 9669 ssh2
Jan 17 21:26:59 shubashi sshd[3717267]: Invalid user [redacted] from 38.250.149.61 port 9713
Jan 17 21:26:59 shubashi sshd[3717267]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=38.250.149.61
Jan 17 21:27:02 shubashi sshd[3717267]: Failed password for [redacted] from 38.250.149.61 port 9713 ssh2
...
show less
(smtpauth) Failed SMTP AUTH login from 38.250.149.61 (PE/Peru/-): 5 in the last 3600 secs; Ports: 25 ...
show more(smtpauth) Failed SMTP AUTH login from 38.250.149.61 (PE/Peru/-): 5 in the last 3600 secs; Ports: 25,465,587; Direction: 0; Trigger: LF_SMTPAUTH; Logs: 2026-01-13 14:24:19 dovecot_plain authenticator failed for H=(DESKTOP-OERUNNA) [38.250.149.61]:9533: 535 Incorrect authentication data
2026-01-13 14:24:32 dovecot_plain authenticator failed for H=(DESKTOP-OERUNNA) [38.250.149.61]:9631: 535 Incorrect authentication data
2026-01-13 14:24:37 SMTP call from [38.250.149.61]:9674 dropped: too many syntax or protocol errors (last command was "?\034?\032?\027?\031?\034?\033?\030?\032?\026?\016?\r?\v?\f?\t?", NULL)
2026-01-13 14:28:14 dovecot_plain authenticator failed for H=(DESKTOP-OERUNNA) [38.250.149.61]:10504: 535 Incorrect authentication data ([email protected])
2026-01-13 14:28:24 dovecot_plain authenticator failed for H=(DESKTOP-OERUNNA) [38.250.149.61]:10534: 535 Incorrect authentication data (set_id=73779639d)
show less
Brute-Force
SSH
Anonymous
scanning http requests from known botnet
Web App Attack
Anonymous
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.11.03 is noted in report tim ...
show moreAttempted brute force login to web vpn 1 time(s); last attempt for 2025.11.03 is noted in report timestamp
show less